Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Email Subscribers & Newsletters
Icegram
Developer
5.9.11
Latest version
70,000
Installations
5 days ago
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Vulnerability history
0 present
26 fixed
10 Mitigation rules
Missing Authentication to Unauthenticated Mailing Queue Trigger vulnerability
<= 5.9.10
6 hours ago
Admin+ Stored XSS in Template vulnerability
< 5.7.50
Apr 25, 2025
Admin+ Stored XSS vulnerability
< 5.7.52
Apr 17, 2025
Admin+ Stored XSS vulnerability
< 5.7.45
Jan 13, 2025
Admin+ SQL Injection vulnerability
< 5.7.44
Jan 6, 2025
Authenticated (Subscriber+) Arbitrary Shortcode Execution vulnerability
<= 5.7.34
Oct 2, 2024
Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure vulnerability
<= 5.7.34
Sep 26, 2024
Missing Authorization vulnerability
<= 5.7.26
Jul 17, 2024
Unauthenticated SQL Injection vulnerability
<= 5.7.25
Jun 26, 2024
Unauthenticated SQL Injection vulnerability
<= 5.7.23
Jun 20, 2024
Authenticated (Subscriber+) SQL Injection Vulnerability via options[list_id] vulnerability
<= 5.7.22
Jun 12, 2024
Unauthenticated SQL Injection via hash vulnerability
<= 5.7.20
Jun 5, 2024
Missing Authorization in handle_ajax_request vulnerability
<= 5.7.19
May 15, 2024
Unauthenticated SQL Injection vulnerability
<= 5.7.14
Apr 16, 2024
Authenticated (Administrator+) Cross-Site Scripting via CSV import vulnerability
<= 5.7.15
Apr 8, 2024
Broken Access Control vulnerability
<= 5.7.13
Apr 5, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 5.7.11
Mar 26, 2024
Authenticated (Administrator+) Directory Traversal to Arbitrary File Read vulnerability
<= 5.6.23
Oct 12, 2023
CSV Injection
<= 5.5.2
Feb 6, 2023
Unauthenticated email forgery/spoofing vulnerability
<= 4.5.5
Sep 10, 2020
Authenticated SQL injection (SQLi) vulnerability
<= 4.5.0.1
Jul 17, 2020
Cross-Site Request Forgery (CSRF) vulnerability
<= 4.5.0.1
Jul 17, 2020
Multiple security issues
<= 4.2.2
Nov 13, 2019
Cross-Site Scripting (XSS) vulnerability
<= 4.1.6
Aug 14, 2019
Missing Function Level Access Control vulnerability
<= 3.4.7
Jan 19, 2018
Multiple Vulnerabilities
<= 2.9
Aug 10, 2015